216.73.217.22

CVE-2025-49521

· Published 30/06/2025 21:15 · Modified 01/07/2025 02:15

Labels: CVE-2025-49521 2025-06-30CVE-2025-49521CWE-94[email protected]

Essential information

Published
30/06/2025 21:15
Modified
01/07/2025 02:15
Author
Creator
CVSS
8.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

A flaw was found in the EDA component of the Ansible Automation Platform, where user-supplied Git branch or refspec values are evaluated as Jinja2 templates. This vulnerability allows authenticated users to inject expressions that execute commands or access sensitive files on the EDA worker. In OpenShift, it can lead to service account token theft.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
redhat / ansible automation platform cpe:2.3:a:redhat:ansible_automation_platform:*:*:*:*:*:*:*:*

References